CISA - Protection of Information Assets - Section 5.2

Assess security testing and monitoring tools and techniques, incident response management, and evidence collection and forensics.

Compare security testing tools and security monitoring techniques - including vulnerability scanning, penetration testing and SIEM-based alerting - and explain when each is appropriate. Evaluate incident response management processes and the evidence collection and digital forensics practices that preserve chain of custody for investigation and legal proceedings.

security testing toolssecurity monitoringincident responseevidence collectiondigital forensics

Practice question for this objective

Free sampleProtection of Information Assetshard

An IS auditor is comparing vulnerability assessment with penetration testing for a retail web estate. The chief information security officer has asked which technique should anchor the quarterly assurance cycle to give the broadest view of weaknesses on internet-facing hosts. Which response BEST reflects the appropriate selection?

  • AQuarterly penetration testing anchors the cycle because exploitation evidence is the only credible indicator that a weakness is real.
  • BConfiguration baseline review anchors the cycle because hardening drift is the dominant source of internet-facing weakness on web hosts.
  • CAuthenticated vulnerability assessment anchors the cycle because it enumerates weaknesses broadly across hosts and informs targeted penetration testing. Correct
  • DBug bounty intake anchors the cycle because crowdsourced research catches weaknesses that internal testing teams routinely overlook on production sites.
Distinguish vulnerability assessment from penetration testing by their coverage and depth, and select the technique that fits the assurance objective. Vulnerability assessment enumerates weaknesses broadly and repeatably, which is the right tool when the audit objective is coverage across a large estate. Penetration testing then verifies exploitability against the riskier findings. Anchoring the quarterly cycle on the broader technique gives management a defensible inventory, with deep testing layered on top.

Why A is wrong: Exploitation evidence is valuable but slow and narrow; relying on it for breadth across an estate misses the catalogue of weaknesses a scanner would surface in the same window.

Why B is wrong: Baseline review is useful, but it addresses configuration drift rather than the full catalogue of missing patches, weak components and exposed services that a vulnerability assessment finds.

Why C is correct: Authenticated scanning gives breadth and patch-state visibility across the estate, which is the right tool for quarterly coverage; penetration testing is then targeted at the riskier findings.

Why D is wrong: Bounty programmes are a useful supplement, but they cannot guarantee coverage or cadence and they leave management without a structured quarterly inventory of weaknesses.

See more CISA practice questions, answers explained.

More in this domain

Back to all Protection of Information Assets objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.